CVE-2025-11182: File Download in GTONE ChangeFlow
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Download of Code Without Integrity Check vulnerability in GTONE ChangeFlow allows Path Traversal.This issue affects ChangeFlow: All versions to v9.0.1.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11182?
CVE-2025-11182 is classified as a medium severity vulnerability due to potential unauthorized access to sensitive files.
How do I fix CVE-2025-11182?
To fix CVE-2025-11182, upgrade GTONE ChangeFlow to version 9.0.1.2 or later, which contains the necessary security patches.
What impact does CVE-2025-11182 have on GTONE ChangeFlow?
CVE-2025-11182 allows attackers to exploit path traversal vulnerabilities to access restricted directories, potentially leading to unauthorized code execution.
Is CVE-2025-11182 present in all versions of GTONE ChangeFlow?
Yes, CVE-2025-11182 affects all GTONE ChangeFlow versions up to and including 9.0.1.1.
How can I determine if my GTONE ChangeFlow installation is vulnerable to CVE-2025-11182?
Check the version of your GTONE ChangeFlow installation; if it is version 9.0.1.1 or earlier, it is vulnerable to CVE-2025-11182.